Jump to content
Freedom in the Digital Age
Art. 1, 2, 10

Report security vulnerabilities or keep them secret?

A new expert opinion commissioned by the GFF outlines what an effective government vulnerability management system might look like

Many cyber-attacks exploit unknown IT security vulnerabilities as a point of entry. How should the government deal with this when security agencies become aware of such vulnerabilities?

You can download the expert opinion here (German).

Please note that this is a machine-translated version of our German landing page.

Municipal administrations that remain only partially available to citizens for months on end, hospitals that are forced to turn away emergency patients: cyberattacks can have serious consequences in a digital society. Points of entry are often errors or vulnerabilities in an IT system or software that enable criminals or state actors to penetrate the system. This allows them to manipulate data or spy on communications – politicians, journalists and activists are often targeted in this way.

Unknown vulnerabilities are particularly dangerous

If such vulnerabilities are still unknown even to the manufacturers themselves, they are referred to as zero-day vulnerabilities. They pose a particular risk because users of the affected software cannot protect themselves against them with patches or updates. Newly discovered security vulnerabilities should therefore be patched immediately upon becoming known.

Among the actors who learn about such zero-day vulnerabilities are security agencies – such as the police and intelligence services. However, it is precisely these agencies that often have an interest in keeping the vulnerabilities secret – and thus unpatched – so that they can exploit them for their own purposes: for example, to search the smartphones of suspects using state-sponsored malware.

Statements on intelligence service reform

Plans to reform intelligence legislation, presented in July 2026, provide for the German Federal Intelligence Service (BND) and the Federal Office for the Protection of the Constitution (BfV) to be permitted to carry out so-called ‘hackbacks’ in future – that is, to conduct active cyber operations themselves. A further draft bill, the Draft Act to Strengthen Cybersecurity, provides for the Federal Police and the Federal Criminal Police Office (BKA) to be granted such powers as well.

Secret zero-day vulnerabilities are also of central importance for hackbacks. From a civil rights perspective, hackbacks pose a problem. Further information on this can be found in the statement (German) that the GFF submitted as part of the consultation with interested parties on the reform of the intelligence services. This issue is also addressed in a submission (German) prepared by Dr Peter Schantz at the GFF’s request for the consultation.

Exploit or patch – a conflict of objectives

The state therefore faces a conflict of interests when it comes to zero-day vulnerabilities: on the one hand, they can be valuable for the work of the security authorities. On the other hand, however, if left unpatched, these vulnerabilities can jeopardise citizens’ security. To protect them, the state should actually act as quickly as possible to close these security gaps. This is also required by the so-called fundamental IT right: the state must protect the integrity and confidentiality of digital systems.

Cyber threats are constantly growing. Citizens and businesses must be able to rely on the state to responsibly deal with IT vulnerabilities and spyware.”
Prof. Dr. Thomas Wischmeyer, Professor of Public Law, specialising in Administrative Law, at Humboldt University of Berlin and co-author of the expert opinion

It follows from the Basic Law that the legislature must establish a procedure to resolve such conflicts of interest. In practical terms, this means that if a law enables the state to exploit digital vulnerabilities, it must also lay down general rules on how the state is required to deal with unknown IT security vulnerabilities and ensure the safety of citizens. Such a law must also specify the extent to which state bodies are permitted to purchase and use external spyware that itself exploits vulnerabilities.

The Federal Constitutional Court has ruled, in a decision on IT security vulnerabilities, that the legislature must introduce such a vulnerability management system. We secured this ruling back in 2021. Nevertheless, no such regulation currently exists in Germany.

A functioning vulnerability management system

The expert opinion (German) commissioned by the GFF and prepared by Prof. Dr. Thomas Wischmeyer and Dr. Paul Friedl addresses this issue. It shows that a law must mandatorily regulate the following requirements for vulnerability management:

  • The legislature must provide for a structured procedure to decide which unknown IT vulnerabilities should remain unpatched. This procedure must weigh the risks and benefits.
  • The legislature must determine which institution is responsible for these decisions and lay down the broad outlines of the procedure.
  • The law must stipulate that the state may keep security vulnerabilities secret only in exceptional cases and for a limited period – as a rule, therefore, it must disclose them. Authorities that keep vulnerabilities secret must take measures to minimise the negative consequences of their decision. They must also review their decisions on an ongoing basis.
  • An independent supervisory body must be able to effectively review the decisions made by the authorities.

Only the details may be regulated in a statutory instrument, which can be adapted more flexibly to technical and organisational changes than a law.

Zero-day vulnerabilities and commercial spyware pose a systemic threat to society as a whole. That is why their use by state actors requires clear rules.
Dr. Paul Friedl, Research Fellow at the Chair of Civil Law and Digital Law at Humboldt University of Berlin and co-author of the expert report

The authors also conclude that the law must mandatorily regulate how state bodies deal with external cyber capabilities: Public authorities are obliged to ensure the protection of fundamental rights even when, for example, they rely on commercial spyware providers. In addition to a comprehensive ban on commercial spyware, it would also be conceivable, amongst other things, to introduce an obligation to assess providers and products, as well as accompanying protective measures – in particular, appropriate sanction mechanisms.

Furthermore, the expert report makes further recommendations on how the law could be specifically structured:

  • An inter-agency and inter-ministerial body should be established as the decision-making body.
  • The authors also recommend entrusting the Independent Supervisory Board with legal oversight and introducing a reporting obligation to the Parliamentary Oversight Committee.
Grundrechte verteidigen.